P4T12ICK
a4ef2443cd
appinspect failing fixes
2025-10-17 07:49:47 +02:00
Michael Haag
a548ed769a
Hellcat United ( #3723 )
...
* Hellcat United
* fixes
* 🍱
* 1 mas
* Update powershell_4104_hunting.yml
2025-10-16 16:53:02 -07:00
Michael Haag
64ed5bb1e8
APT 37 and The No Good Rustonotto ( #3686 )
...
* APT 37 and The No Good Rustonotto
## Updated analytics
```
detections/application/detect_html_help_spawn_child_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/bitsadmin_download_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/cobalt_strike_named_pipes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_html_help_using_infotech_storage_handlers.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_renamed.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_mshta_url_in_command_line.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_outlook_exe_writing_a_zip_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/detect_rundll32_inline_hta_execution.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/executables_or_script_creation_in_temp_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/icedid_exfiltrated_archived_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/lolbas_with_network_traffic.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/mshta_spawning_rundll32_or_regsvr32_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_4104_hunting.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/powershell_fileless_script_contains_base64_encoded_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/processes_tapping_keyboard_events.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/recursive_delete_of_directory_in_batch_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/registry_keys_used_for_persistence.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_curl_network_connection.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_image_creation_in_appdata_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_mshta_spawn.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_process_executed_from_container_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/suspicious_scheduled_task_from_public_directory.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_alternate_datastream___base64_content.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archive_collected_data_via_rar.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_archived_collected_data_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_boot_or_logon_autostart_execution_in_startup_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_cab_file_on_disk.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_curl_download_to_suspicious_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_invoke_restmethod.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_exfiltration_over_c2_via_powershell_uploadstring.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_file_download_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_high_file_deletion_frequency.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_http_network_communication_from_msiexec.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_indicator_removal_via_rmdir.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_input_capture_using_credential_ui_dll.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_iso_lnk_file_creation.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_obfuscated_files_or_information_via_rar_sfx.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_dropped_cab_or_inf_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_child_process_for_download.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_office_product_spawned_uncommon_process.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_executed_from_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_execution_from_programdata.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_commonly_abused_processes.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_process_injection_into_notepad.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_replication_through_removable_media.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_command.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_scheduled_task_with_suspicious_name.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_in_temp_folder.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_screen_capture_via_powershell.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_service_created_with_suspicious_service_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_spearphishing_attachment_onenote_spawn_mshta.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_suspicious_driver_loaded_path.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_system_binary_proxy_execution_compiled_html_file_decompile.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_usbstor_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_user_execution_malicious_url_shortcut_file.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_wpdbusenum_registry_key_modification.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/winevent_scheduled_task_created_within_public_path.yml — APT37 Rustonotto and FadeStealer
detections/web/multiple_archive_files_http_post_traffic.yml — APT37 Rustonotto and FadeStealer
detections/web/plain_http_post_exfiltrated_data.yml — APT37 Rustonotto and FadeStealer
detections/endpoint/windows_expand_cabinet_file_extraction.yml — APT37 Rustonotto and FadeStealer
```
## New Story
```
stories/apt37_rustonotto_and_fadestealer.yml — APT37 Rustonotto and FadeStealer
```
* Create windows_expand_cabinet_file_extraction.yml
* Apply suggestion from @nasbench
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* Update detections/endpoint/windows_expand_cabinet_file_extraction.yml
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
* updating conflicts
---------
Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com >
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com >
Co-authored-by: Bhavin Patel <bpatel@splunk.com >
2025-10-13 13:54:03 -07:00
Michael Haag
b6083e5076
GhostRedirectors
2025-09-18 13:39:40 -06:00
Teoderick Contreras
96786372a3
interlock_ransomware
2025-07-28 11:58:45 +02:00
Michael Haag
4e3598c522
Update windows_sharepoint_toolpane_endpoint_exploitation_attempt.yml
2025-07-21 13:11:43 -06:00
Michael Haag
c5838d60da
Create windows_sharepoint_spinstall0_get_request.yml
2025-07-21 09:28:05 -06:00
Michael Haag
13b49f5456
Sharing is Caring: A story of CVE-2025-53770
2025-07-20 17:03:37 -06:00
Nasreddine Bencherchali
523e5f4b94
add ftd equivalent analytic
2025-07-17 20:43:29 +02:00
Nasreddine Bencherchali
483e79feae
Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
...
update formatting
2025-07-17 14:56:14 +02:00
Michael Haag
c6af7c5b52
Update citrix_adc_and_gateway_citrixbleed_2_memory_disclosure.yml
2025-07-09 11:49:23 -06:00
Michael Haag
b74094eb74
CitrixBleed2
2025-07-02 10:33:13 -06:00
ljstella
397107f88a
Updated docs links in detections
2025-06-24 11:27:59 -05:00
Eric
d9960562b8
Bump versions for every detection, since everything will have a different conf stanza due to added fields. Don't re-bump things that already had their version bumped after the last release - this is a check that now causes a contentctl inspect failure. Finally, update all of the versions to today since this is the last time that the contents of the stanza is different.
2025-05-02 14:10:46 -07:00
Michael Haag
074d13f001
BasketNetWeaving with Haag: No Shell Left Behind!
2025-04-28 10:33:17 -06:00
Bhavin Patel
bb2045cce0
Merge branch 'develop' into crushingit
2025-04-18 12:45:18 -07:00
Michael Haag
9f8f28c0b5
Update crushftp_max_simultaneous_users_from_ip.yml
2025-04-18 13:27:09 -06:00
Michael Haag
95049154e9
Update crushftp_authentication_bypass_exploitation.yml
2025-04-18 13:25:39 -06:00
Bhavin Patel
8e6d4c69bf
Merge branch 'develop' into remove_v5.4.0
2025-04-17 12:00:27 -07:00
Michael Haag
657ffbc9e4
Ground Control to Major Haag: Earth Alux
...
This PR adds a new analytic story for the Earth Alux threat actor, a sophisticated espionage group targeting government, technology, and telecommunications sectors in APAC and Latin America.
2025-04-16 21:55:12 -06:00
Bhavin Patel
5b7cfdb7d3
updating versions
2025-04-16 16:45:16 -07:00
Michael Haag
fc81c76727
Haag's Crushed Shell: A Tale of CrushFTP Exploitation
...
CVE-2025-31161
2025-04-14 12:39:07 -06:00
Bhavin Patel
00253f3c6e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 14:45:19 -07:00
Bhavin Patel
7168e32ea6
Merge branch 'develop' into sunnyside
2025-04-01 14:05:53 -07:00
Michael Haag
55b5bc77d2
fixagai
2025-04-01 14:48:54 -06:00
Michael Haag
f435240b83
fixes
2025-04-01 14:34:18 -06:00
Patrick Bareiss
7541027f8e
Merge branch 'develop' into output_normalization_endpoint
2025-04-01 09:41:58 +02:00
Michael Haag
20cb4400dc
Haag Story 3: Attack Analytics to the Rescue
...
"There's a snake in my Tomcat!"
When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe.
This PR delivers:
- Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt
- A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story
- No more crying when the bad toys try to upload .session files
- The claw of justice comes down when suspicious JSESSIONID cookies appear
Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"
2025-03-25 14:08:02 -06:00
Michael Haag
ec5cf468e3
The Haag Identity: Operation Seashell Blizzard 🌊 ❄️
...
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include:
Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately.
Analytics tagged with "Seashell Blizzard" include:
ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal)
Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell)
Credential access monitoring (LSASS dumps via TaskMgr and ProcDump)
Remote access software usage detections (file, process, registry)
Scheduled task abuse detections
SQL Server xp_cmdshell configuration changes
Registry hive dumping detection
Key updates:
- Added "Seashell Blizzard" tag to 20 existing detections
These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.
2025-03-24 14:18:40 -06:00
Patrick Bareiss
1c9debe9a6
update versions
2025-03-14 13:47:44 +01:00
Patrick Bareiss
67dff5120a
Merge branch 'develop' into output_normalization_endpoint
2025-03-13 09:22:06 +01:00
pyth0n1c
d77736f7e4
Update detect_web_access_to_decommissioned_s3_bucket.yml
...
fix tests key again
2025-02-20 14:57:35 -08:00
Jose Hernandez
36f3b6eb35
shipping as experimental
2025-02-20 17:11:38 -05:00
Jose Hernandez
441ba47f3d
fixing merge conflicts
2025-02-20 17:06:33 -05:00
pyth0n1c
fde93c6d32
convert csv lookup to kvstore lookup.
...
Update references in description files
as well.
2025-02-19 14:50:53 -08:00
research-bot
ddf3ed0797
adding baseline key to test
2025-02-18 08:49:59 -08:00
research-bot
43c999440c
updating yamls
2025-02-18 08:42:18 -08:00
research-bot
2d54affae2
updating dummy dataset links
2025-02-13 17:30:11 -08:00
research-bot
0ec052b8f9
updating yaml to pass build and adding lookup, minor fixes
2025-02-13 15:36:01 -08:00
Jose Hernandez
d83efc4dd1
adding datasets
2025-02-13 16:58:01 -05:00
Jose Enrique Hernandez
fda0c88916
Merge branch 'develop' into 8_million_requests
2025-02-13 16:42:17 -05:00
Jose Hernandez
172e1d5db5
first draft
2025-02-12 18:03:06 -05:00
pyth0n1c
45599e0b18
Clean up MITRE Tagging. When a type is defined, such as T1003, DO NOT allow a subtype such as T1003.001 to be defined. Remove the generic type T1003 and keep the subtype T1003.001. However, it is acceptable for a subtype to be defined or for a type to be defined separately. It is also okay for multiple subtypes to be defined.
2025-02-10 12:28:22 -08:00
Steven Dick
41c92476b9
Update detect_remote_access_software_usage_url.yml
2025-02-06 08:04:38 -05:00
Steven Dick
7773664924
Update detect_remote_access_software_usage_url.yml
2025-02-06 07:57:46 -05:00
research-bot
76a9a02c9e
updating versions
2025-02-05 10:49:03 -08:00
research-bot
6c3e7df1ad
notable to finding 2
2025-01-24 17:03:47 -08:00
Nasreddine Bencherchali
c0418cff2e
Merge branch 'develop' of https://github.com/splunk/security_content into major-updates
2025-01-22 11:40:26 +01:00
Michael Haag
8ce3783394
Update windows_exchange_autodiscover_ssrf_abuse.yml
...
- Updated detection description to better explain ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) attack patterns
- Enhanced search query:
- X-Rps-CAT parameter
- Suspicious user agent strings
2025-01-16 10:02:05 -07:00
pyth0n1c
fdaa038eab
Finish removing extra fields, or renaming
...
misnamed fields, in endpoint detections
2025-01-03 15:47:32 -08:00